Fetching description from NVD…
Show 1 repositories
CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE published
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE published
Fetching description from NVD…
Sudo Baron Samedit Exploit
PoC for CVE-2021-3156 (sudo heap overflow)
CVE-2021-3156 - Sudo Baron Samedit
CVE-2021-3156非交互式执行命令
Root shell PoC for CVE-2021-3156
CVE-2021-3156
clif is a command-line interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. It was inspired by sudo vulnerability CVE-2021-3156 and …
Fetching description from NVD…
Fetching description from NVD…
Community-maintained fork of image-size with fixes for CVE-2025-71329 and CVE-2025-71330
Fetching description from NVD…
CVE-2026-76461
CVE-2026-76461
CVE-2026-76461 - Draft or TODO
Fetching description from NVD…
CVE-2026-76460
Fetching description from NVD…
Safe, pure-JS drop-in replacement for bigint-buffer. Fixes CVE-2025-3194 (CVSS 7.5). Zero dependencies, no native bindings.
Pure-JS drop-in for [email protected] without the vulnerable native binding (CVE-2025-3194)
Fetching description from NVD…
CVE-2024-57551, CVE-2024-57552, CVE-2024-57553 advisories by Aman Bahiniya
The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them.
PoC for CVE-2026-92099 on WPGraphQL Smart Cache
Fetching description from NVD…
CVE-2026-19975 - Draft or TODO
Fetching description from NVD…
Technical analysis and proof of concept for CVE-2026-59827, a critical unsafe Java deserialization vulnerability in Metabase leading to remote code execution.
Metabase CVE-2026-59827 Vulnerability Scanner
Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization
Educational cyber range for CVE-2026-59827 (Metabase H2 unsafe deserialization / CWE-502). Isolated Docker lab — training only, not for attacking production Me…
Fetching description from NVD…
CVE-2026-92162: Path traversal in the Flatpak system helper: an unvalidated arch parameter in DeployAppstream lets an active local user create root-owned direc…
Fetching description from NVD…
CVE-2023-20052, information leak vulnerability in the DMG file parser of ClamAV
CVE-2023-20052 information leak vulnerability in the DMG file parser of ClamAV
Working Docker build for the ClamAV XXE exploit (CVE-2023-20052), patched to compile on OpenSSL 3.0
Original standalone Proof-of-Concept exploit and execution harness for CVE-2023-20052 (ClamAV DMG XML Entity Expansion).
Fetching description from NVD…
Fetching description from NVD…
PoC for popping a system shell against the LnvMSRIO.sys driver
Exploit LnvMSRIO.sys vulnerable driver
PoC to exploit lenovo dispatcher driver (LnvMSRIO.sys) (CVE-2025-8061)
MSRMapper is a manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in the vulnerable Lenovo driver LnvMSRIO.sys to perform a BYOVD (Bring You…
My PoC of Lenovo-CVE-2025-8061
Fetching description from NVD…
This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCM…
CraftCMS RCE Checker (CVE-2025-32432)
Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail
Exploit, POC for CVE-2025-32432, CraftCMS2Shell
AI修复生成的CVE-2025-32432的poc
Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research
Fetching description from NVD…
Unbounded memory allocation in NanaZip's UFS handler via an attacker-controlled `fs_bsize` field.
Fetching description from NVD…
CutePHP Cute News 2.1.2 RCE PoC
CuteNews Avatar 2.1.2 Remote Code Execution Vulnerability
CuteNews 2.1.2 - CVE-2019-11447 Proof-Of-Concept
Exploits CuteNews 2.1.2 via poor file upload checks used when uploading an avatar image leading to RCE.
Exploit Code for CVE-2019-11447 aka CuteNews 2.1.2 Avatar upload RCE (Authenticated)
CPTS HackTheBox - Penetration Test Report: WordPress Path Traversal CVE-2019-11447
Fetching description from NVD…
CVE-2021-43287_GoCD_fileread_POC_EXP
CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290
Fetching description from NVD…
Authorized security-research lab reproducing CVE-2026-44246 (GHSA-63mx-j37w-gh59): prompt injection via verbatim issue title/body inlining into the claude-code…
Reproducible vulnerable/fixed fixtures for agentic workflow injection in GitHub Actions (CVE-2026-44246), plus measured detector coverage
Fetching description from NVD…
Langflow 1.10.0 urllib SSRF
Fetching description from NVD…
CVE-2026-83991: Windows Cloud Files access-check bypass
Fetching description from NVD…
Explanation and POC of the CVE-2023-23946
Original standalone Proof-of-Concept exploit for CVE-2023-23946 (Git path traversal via crafted patches in git-apply).
Fetching description from NVD…
spip exploits for CVE-2026-72708, CVE-2026-72709, CVE-2026-72710
Fetching description from NVD…
Unofficial Apache Doris Spark connector 26.1.0 security fork for Java / Spark 3.5.1 / Scala 2.12; patched shaded Jackson for CVE-2026-54512.
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.